Anomaly detection device and anomaly detection method
The abnormal detection device adjusts recording and communication of security anomalies based on vehicle state, optimizing load management and ensuring timely reporting.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-09-19
- Publication Date
- 2026-03-26
AI Technical Summary
Existing techniques for controlling the load required for communicating security abnormalities in vehicle networks fail to account for the vehicle's state, leading to inefficient communication.
An abnormal detection device that determines the vehicle's state and adjusts the content and frequency of recording and communicating security anomalies based on this state, using a controller to manage the load effectively.
Enables controlled communication load by adapting to the vehicle's state, reducing processing overhead and costs while ensuring critical anomalies are promptly reported.
Smart Images

Figure JP2024033514_26032026_PF_FP_ABST
Abstract
Description
Abnormal Detection Device and Abnormal Detection Method
[0001] The present invention relates to an abnormal detection device and an abnormal detection method.
[0002] There is known a technique of determining the amount of data and / or timing used for communication with an external device based on the priority according to the type, content, frequency, etc. of the detected abnormality, and performing communication with the external device according to the amount of data and / or timing (Patent Document 1).
[0003] International Publication No. 2023 / 002634
[0004] However, the technique described in Patent Document 1 is a technique for controlling the load required for communicating a security abnormality according to the characteristics of the security abnormality in the in-vehicle network of a vehicle, but there is a problem that the load required for communicating a security abnormality cannot be controlled according to the state of the vehicle.
[0005] The problem to be solved by the present invention is to provide an abnormal detection device and an abnormal detection method that can control the load required for communicating a security abnormality according to the state of the vehicle.
[0006] The present invention determines the state of the vehicle, detects a security abnormality in the in-vehicle network of the vehicle, determines the content of the security abnormality to be recorded and communicated and the frequency of recording and communicating the security abnormality according to the state of the vehicle, and records and communicates the security abnormality according to the determined content and frequency, thereby solving the above problems.
[0007] According to the present invention, the load required for communicating a security abnormality can be controlled according to the state of the vehicle.
[0008] FIG. 1 is a block diagram showing the configuration of an abnormal detection system including the abnormal detection device according to the present embodiment. FIG. 2 is a diagram for explaining the correspondence between each determination element for determining the state of the vehicle and the risk determination in the present embodiment. FIG. 3 is a diagram for explaining the correspondence between the reduction level and the specific method of reducing the load of recording and notification in the present embodiment. FIG. 4 is a diagram showing an example of a flowchart of the abnormal detection method executed by the abnormal detection device according to the present embodiment.
[0009] Embodiments of the present invention will be described below with reference to the drawings. In this embodiment, an example will be described in which the anomaly detection device and anomaly detection method according to the present invention are applied to anomaly detection in an in-vehicle network system (not shown) mounted on an automobile (also referred to as a vehicle). In the in-vehicle network system according to this embodiment, for example, a plurality of ECUs (Electronic Control Units) are connected to each other by an in-vehicle network such as a CAN (Controller Area Network), that is, each ECU can send and receive data with other ECUs using a CAN bus or the like. The ECUs include, for example, a body system ECU, a driving system ECU, a power system ECU, a multimedia system ECU, and the like. In this embodiment, an anomaly detection system equipped with an anomaly detection device detects a security anomaly in the vehicle's in-vehicle network and notifies a monitoring system located outside the vehicle of the security anomaly.
[0010] Figure 1 is a block diagram showing the configuration of an anomaly detection system including an anomaly detection device according to this embodiment. The anomaly detection system 1 comprises various devices mounted on the vehicle 2 and a monitoring system 3. The various devices mounted on the vehicle 2 include an anomaly detection device 10 and an external communication device 20. The anomaly detection device 10 is connected to each ECU mounted on the vehicle 2 via an in-vehicle network (not shown). The anomaly detection device 10 exchanges information with the monitoring system 3 via the external communication device 20. The monitoring system 3 is a system located outside the vehicle 2 that monitors and analyzes security anomalies in the vehicle's in-vehicle network. For example, the monitoring system 3 is installed in a security operation center, and an operator or other manager monitors the vehicle's in-vehicle network via a monitor. In this embodiment, the monitoring system 3 may monitor security anomalies in the in-vehicle networks of multiple vehicles 2.
[0011] Each ECU is an electronic control unit that controls in-vehicle equipment mounted on vehicle 2. Each ECU is connected to in-vehicle equipment such as sensors or actuators and controls various types of in-vehicle equipment. Each ECU comprises a processor and a communication circuit. The processor comprises a CPU, a ROM that stores the control program executed by the CPU, and RAM used as a work area for the control program. The processor functions as an ECU by executing the control program using the CPU. The communication circuit is controlled by the processor and communicates between the processor and the in-vehicle network. In this embodiment, the abnormality detection device 10 is also one of the ECUs mounted on vehicle 2.
[0012] The anomaly detection device 10 is, for example, a master ECU. The master ECU is a higher-level ECU in the in-vehicle network and is a control unit connected to an upstream position on the in-vehicle network. The anomaly detection device 10 includes a controller 100. The controller 100 includes a computer having hardware and software, which includes a ROM that stores a control program, a CPU that executes the control program stored in the ROM, and RAM that functions as an accessible storage device. The storage location of the control program is not limited to ROM, but can be any storage medium that the computer can read, and the location of the storage medium may be inside or outside the controller 100.
[0013] The controller 100 includes, as functional blocks, a vehicle state determination unit 101, a detection unit 102, a recording information generation unit 103, a recording unit 104, a notification unit 105, and a reading unit 106. In this embodiment, the controller 100 executes each of the above functions through the cooperation of software for realizing each of the above functions or executing each of the above processes with the hardware described above. More specifically, these functions are realized by the CPU executing a control program recorded in ROM. In this embodiment, the functions of the controller 100 are divided into six blocks and the functions of each functional block are described, but the functions of the controller 100 do not necessarily have to be divided into six blocks, and may be divided into six or fewer functional blocks, or six or more functional blocks.
[0014] The vehicle state determination unit 101 determines the state of the vehicle 2. The state of the vehicle 2 includes the state of the surrounding environment of the vehicle 2 and / or the vehicle state of the vehicle 2. For example, the state of the vehicle 2 includes at least one of the following: the weather around the vehicle 2, the temperature around the vehicle 2, the time of day the vehicle 2 is traveling, the road surface the vehicle 2 is traveling on, the location the vehicle 2 is traveling on, the speed state of the vehicle 2, the steering state of the vehicle 2, the parking location of the vehicle 2, and the autonomous driving execution state of the vehicle 2. The vehicle state determination unit 101 determines the state of the vehicle 2 for each of these determination elements used to determine the state of the vehicle 2. In this embodiment, each determination element has a predetermined set of categories representing the state of the vehicle 2. At regular intervals, the vehicle state determination unit 101 acquires detection information from the vehicle 2's onboard equipment to the inside and outside of the vehicle 2, and based on the acquired detection information, determines for each determination element which of the predetermined categories the state of the vehicle 2 corresponds to. The detection information is acquired from the onboard equipment via each ECU. The status of vehicle 2 is determined, for example, at regular intervals while the vehicle's power is on. This allows the vehicle's status to be determined in real time.
[0015] The in-vehicle equipment includes, for example, sensors, communication devices, and vehicle information acquisition devices. Specifically, the vehicle state determination unit 101 acquires wiper operation information from the vehicle information acquisition device and determines the weather around the vehicle 2 based on the wiper operation information. The vehicle state determination unit 101 may also acquire detection information from a rain sensor indicating the amount of raindrops detected and determine the weather around the vehicle 2 based on the detection information. The weather can be divided into categories such as rain, cloudy, and sunny. The vehicle state determination unit 101 acquires detection information from a temperature sensor indicating the temperature around the vehicle 2 and determines the ambient temperature around the vehicle 2 based on the detection information. The ambient temperature can be divided into categories such as low temperature (freezing), high temperature, and ambient temperature.
[0016] The vehicle status determination unit 101 acquires the current time information from the GPS device and determines the time period during which the vehicle 2 is traveling. The vehicle status determination unit 101 also acquires detection information from the light sensor that detects the brightness around the vehicle 2 and determines the time period during which the vehicle 2 is traveling based on the detection information. The time period can be divided into categories such as nighttime, sunrise, before sunset, and daytime. The vehicle status determination unit 101 also acquires detection information from the G sensor that detects vibrations of the vehicle 2 and determines the road surface on which the vehicle 2 is traveling based on the detection information. The road surface can be divided into categories such as rough terrain, leveled roads, and paved roads.
[0017] The vehicle status determination unit 101 acquires map information from a map database and determines the location where the vehicle 2 is traveling based on the map information. Alternatively, the vehicle status determination unit 101 may acquire location information of the vehicle 2 from a GPS device and determine the location where the vehicle 2 is traveling based on the location information of the vehicle 2. The locations can be divided into categories such as highways, sharp curves, slopes, bridges, tunnels, curves, and general roads. The vehicle status determination unit 101 may also acquire wheel speed information, shift position information, map information, and location information and determine the parking or stopping location where the vehicle 2 is parked or stopped based on the wheel speed information, shift position information, map information, and location information. The parking or stopping locations can be divided into categories such as parking lots, factories / dealerships, and other locations. For example, the vehicle status determination unit 101 first determines whether the vehicle 2 is parked or stopped based on the wheel speed information and shift position information. If the vehicle 2 is determined to be parked or stopped, the vehicle status determination unit 101 determines the parking or stopping location where the vehicle 2 is traveling based on map information and / or location information.
[0018] The vehicle state determination unit 101 acquires the vehicle's speed from the wheel speed sensor and vehicle speed sensor, and determines the vehicle's speed state based on the vehicle's speed. Speed states are divided into categories such as high speed, medium-low speed, and stopped. The vehicle state determination unit 101 determines that the vehicle's speed state is high speed if the vehicle's speed is above a predetermined speed. The vehicle state determination unit 101 acquires the steering angle of the vehicle from the steering angle sensor and yaw rate sensor, and determines the steering state of the vehicle based on the steering angle. Steering states are divided into categories such as large steering, medium steering, and neutral. The vehicle state determination unit 101 determines that the vehicle's steering state is large steering if the vehicle's steering angle is above a predetermined steering angle. The vehicle state determination unit 101 acquires automated driving information for the vehicle from the automated driving system, and determines the automated driving execution state of the vehicle based on the automated driving information. Autonomous driving information includes whether autonomous driving is being performed and whether the autonomous driving function is available. The autonomous driving status can be categorized, for example, as autonomous driving in progress, autonomous driving stopped, or autonomous driving function unavailable.
[0019] In this embodiment, the vehicle status determination unit 101 may also determine the risk to the safety of vehicle 2 in the event of a security anomaly, depending on the state of vehicle 2. The risk is the risk to the safety of vehicle 2 in the event of a security anomaly in the in-vehicle network. The risk is pre-classified into multiple levels. For example, the risk can be divided into four levels: high risk, medium risk, low risk, and very low risk. Note that the risk classification is not limited to four levels; it may also be three or fewer levels, or five or more levels. The risk classification is pre-set for each determination element to correspond to each level of the state of vehicle 2. The vehicle status determination unit 101 determines the corresponding risk level according to the level of each determination element that it has determined. Note that in this embodiment, risk determination is not an essential configuration and may be adopted as needed. For example, the vehicle status determination unit 101 outputs the determination result of the determined state of vehicle 2 to the recording unit 104 and the notification unit 105. In this case, the recording unit 104 and the notification unit 105 determine the content and frequency of recording and communication according to the state of the vehicle.
[0020] Here, an example of the risk determination method in this embodiment will be explained using Figure 2. Figure 2 is a diagram illustrating the correspondence between each determination element for determining the state of the vehicle in this embodiment and the risk determination. In Figure 2, for each determination element for determining the state of the vehicle 2, the correspondence between each category representing the state of the vehicle 2 and the risk category is shown. As shown in Figure 2, if there is no category corresponding to a risk category (very low risk) for each category of determination element, the determination element is classified as "NA" (Not Applicable). For example, if the determination element is "weather," each category representing "weather" (rain, cloudy, sunny, NA) is associated with a risk category (high risk, medium risk, low risk, very low risk). The vehicle state determination unit 101 refers to a table as shown in Figure 2 according to the state of the vehicle and determines the risk category for each determination element of the vehicle state.
[0021] Furthermore, the vehicle state determination unit 101 may determine whether the state of vehicle 2 is in a predetermined critical state. The predetermined critical state includes, for example, the state in which vehicle 2 is performing automatic driving. That is, if vehicle 2 is performing automatic driving, the vehicle state determination unit 101 determines that the state of vehicle 2 is in a predetermined critical state. If the state of vehicle 2 is in a predetermined critical state, that is, if vehicle 2 is performing automatic driving, the vehicle state determination unit 101 determines the risk to be the highest. For example, the vehicle state determination unit 101 determines it to be a risk category higher than "high risk" in the risk categories described above. As will be described later, if the state of vehicle 2 is in a predetermined critical state, the recording and notification of a security anomaly will be performed according to the normal settings.
[0022] If the vehicle status determination unit 101 is not in a predetermined critical state, it may calculate a risk value according to the result of the risk determination for each determination element. The risk value is a numerical representation of the risk to the safety of the vehicle due to a security anomaly. In this embodiment, a risk value is set for each risk category. For example, the risk value is set to 3 points if the risk category is high risk, 2 points if the risk category is medium risk, 1 point if the risk category is low risk, and 0 points if the risk category is extremely low risk. For example, the vehicle status determination unit 101 calculates a risk value for each determination element according to the risk category and calculates the average value of the risk values for each determination element. The vehicle status determination unit 101 determines the overall risk category, which is a combination of the risks of each determination element, according to the average value of the calculated risk values. For example, if the average risk value is 2.5 to 3, the overall risk is classified as high risk. If the average risk value is 1.5 to 2.5, the overall risk is classified as medium risk. If the average risk value is 0 to 1.5, the overall risk is classified as low risk. Furthermore, the vehicle condition determination unit 101 may set the overall risk to extremely low if, regardless of the risk value, the proportion of determination elements whose risk classification is low is 80% or more of all determination elements. The overall risk may also be set by a majority vote of the risk classifications of each determination element. The determination results and / or calculation results from the vehicle condition determination unit 101 are output to the notification unit 105 and the recording unit 104.
[0023] Here, an example of risk determination in this embodiment will be explained using Figure 2. For example, let's consider a scenario where vehicle 2 is being diagnosed outside a factory or dealership for roadside repairs. For example, suppose the weather is sunny, the temperature is normal, the time of day is daytime, the road surface is paved, the location is a public road, the speed is stopped, the steering is neutral, the parking location is a parking lot, and the autonomous driving state is autonomous driving stopped. In such a case, the vehicle condition determination unit 101 determines that the vehicle 2 is not in a critical state, and more than 80% of the determination elements are classified as low risk, so it determines the risk to be extremely low. Also, let's consider a scenario where vehicle 2 is being diagnosed inside a factory or dealership for roadside repairs. For example, suppose the weather is sunny, the temperature is normal, the time of day is daytime, the road surface is paved, the location is a public road, the speed is stopped, the steering is neutral, the parking location is a factory or dealership, and the autonomous driving state is autonomous driving stopped. In such cases, the vehicle condition determination unit 101 determines that the vehicle 2 is in a critical condition and that 80% or more of the determination elements are classified as low risk, thus determining that the risk is extremely low.
[0024] For example, let's consider a scenario where vehicle 2 is driving on an urban area (public road) without autonomous driving during a summer night in rainy weather. For example, suppose the weather is rainy, the temperature is high, the time of day is nighttime, the road surface is paved, the location is a public road, the speed is medium to low, the steering is in the neutral position, and the autonomous driving state is autonomous driving stopped. In this case, the vehicle state determination unit 101 determines that the state of vehicle 2 is not critical and the average risk value is 1.56, so it is judged to be of medium risk. Another example is a scenario where vehicle 2 is driving on a highway without autonomous driving during a winter night in rainy weather. For example, suppose the weather is rainy, the temperature is low (freezing), the time of day is nighttime, the road surface is paved, the location is a highway, the speed is high, the steering is being steered, and the autonomous driving state is autonomous driving stopped. In this case, the vehicle state determination unit 101 determines that the state of vehicle 2 is not congested and the average risk value is 2.56, so it is judged to be of high risk.
[0025] The detection unit 102 detects security anomalies in the in-vehicle network. Security anomalies in the in-vehicle network include excessive communication attacks from external sources. Such anomalies can cause the ECU to lose functionality, potentially affecting the operation of the vehicle 2. For example, the detection unit 102 detects a security anomaly when the amount of communication data transmitted via the CAN bus exceeds a predetermined amount. The detection unit 102 also detects a security anomaly when the transmission cycle of data frames transmitted via the CAN bus exceeds a predetermined transmission cycle. The results of the security anomaly detection by the detection unit 102 are output to the notification unit 105 and the recording information generation unit 103.
[0026] The recording information generation unit 103 generates information about security anomalies detected by the detection unit 102. The generated information includes detailed information and simplified information. The detailed information contains more detailed content than the simplified information, and the amount of data related to the security anomaly is greater than the amount of data related to the security anomaly included in the simplified information. The detailed information includes, for example, the type of security anomaly, the location where the security anomaly was detected, and the timing when the security anomaly was detected. The simplified information is information that summarizes the content of the security anomaly included in the detailed information. In this embodiment, the types of information generated by the recording information generation unit 103 are not limited to just detailed information and simplified information, but may include three or more different types of information. Each type of information contains a different amount of data related to the security anomaly. For example, if there are three types of information, the data amounts of each type of information can be divided into large, medium, and small. Each piece of information generated by the recording information generation unit 103 is output to the recording unit 104.
[0027] The recording unit 104 records detailed information and / or simplified information, including details related to security anomalies. In this embodiment, the recording unit 104 determines the content of the security anomaly to be recorded and the frequency of recording the security anomaly, according to the determination result and / or calculation result from the vehicle state determination unit 101. For example, the recording unit 104 determines the content and frequency to be recorded such that the amount of data for the security anomaly to be recorded increases and the frequency of recording increases as the risk increases. The recording unit 104 then records the security anomaly according to the determined content and frequency. The risk is, for example, the overall risk obtained by combining the risks in each determination element. The information recorded by the recording unit 104 is output to the notification unit 105 and the reading unit 106. In this embodiment, determining the content and frequency to be recorded according to the risk is not an essential configuration; the content and frequency to be recorded may be determined by other methods as long as they can be determined according to the vehicle state. Furthermore, it is not limited to changing both the content and frequency to be recorded; either one of them may be changed.
[0028] The notification unit 105 notifies notification information that includes details of a security anomaly. The notification unit 105 outputs a notification instruction to the external communication device 20 and transmits the notification information to the monitoring system 3 via the external communication device 20. The notification information only needs to include the detection result of the detected security anomaly, and may be detailed information or simplified information recorded by the recording unit 104.
[0029] In this embodiment, the notification unit 105 changes the content and frequency of notification information to be sent to the monitoring system 3 according to the determination result and / or calculation result by the vehicle status determination unit 101. For example, the notification unit 105 determines the content and frequency of notification so that the amount of data for the security anomaly subject to notification increases as the risk increases, and the frequency of notification of security anomalies increases. The notification unit 105 then transmits the security anomaly to the monitoring system 3 according to the determined content and frequency. The risk is, for example, the overall risk obtained by combining the risks in each determination element. In this embodiment, it is not essential to determine the content and frequency of notification according to the risk; the content and frequency of notification may be determined by other methods as long as they can be determined according to the vehicle status. Furthermore, it is not limited to changing both the content and frequency of notification; either the content or frequency of notification may be changed.
[0030] Here, an example of a method for determining the content and frequency of recording and notification according to the determination result of the vehicle status determination unit 101 will be described. In this embodiment, the recording unit 104 and the notification unit 105 determine a reduction level to reduce the processing load according to the determination result determined by the vehicle status determination unit 101, and execute their respective processes according to the determined reduction level. The reduction level indicates the degree to which the processing load for recording and / or notification processing is reduced. The reduction level is divided into multiple stages. For example, the reduction level is divided into processing stop, large, medium, small, and no reduction. The reduction level is associated with the risk classification. The vehicle status determination unit 101 sets the reduction level according to the risk. The lower the risk, the higher the reduction level is set. When the reduction level is large, the recording unit 104 and the notification unit 105 perform their respective processes in a manner that reduces the processing load compared to when the reduction level is medium. For example, the recording unit 104 records the content of the security anomaly as simplified information or reduces the frequency of recording. The notification unit 105 reduces the frequency of notification. Furthermore, if the reduction level is set to stop processing, the recording unit 104 and the notification unit 105 stop the recording and notification processes. If the reduction level is set to no reduction, the recording unit 104 and the notification unit 105 execute their respective processes as normally set without reducing the load. As described above, in this embodiment, when a security anomaly poses a low risk to vehicle safety, it is possible to reduce the communication load and communication costs associated with recording and notification processes. In addition, when a security anomaly poses a high risk to vehicle safety, it is possible to avoid unnecessarily adjusting the recording and notification of the security anomaly.
[0031] Here, using Figure 3, an example of how to determine the recording and notification methods in this embodiment will be described. Figure 3 is a diagram illustrating the correspondence between the reduction level and the specific method for reducing the recording and notification load in this embodiment. The recording unit 104 and the notification unit 105 set the reduction level according to the risk determined by the vehicle state determination unit 101, for example. Then, the recording unit 104 and the notification unit 105 refer to a table as shown in Figure 3 to determine the content and frequency of security anomalies to be stored and notified in a manner corresponding to the set reduction level. For example, if the state of vehicle 2 is determined to be a critical state, the reduction level is set to no reduction. Also, if the risk is determined to be high risk, medium risk, low risk, or extremely low risk, the reduction level is set to small, medium, large, or processing stopped.
[0032] As shown in Figure 3, when the reduction level is set to no reduction, the recording unit 104 and the notification unit 105 perform their respective processes as per the normal settings. In the normal settings, for example, each process is performed each time the detection unit 102 detects a security anomaly. When the reduction level is low, the recording unit 104 records detailed information or simplified information including the content of the security anomaly, and reduces the recording frequency to a lower level than when the reduction level is medium. That is, when the reduction level is low, the recording unit 104 records security anomalies at a higher frequency than when the reduction level is medium. When the reduction level is low, the notification unit 105 reduces the notification frequency to a lower level than when the reduction level is medium. That is, when the reduction level is low, the notification unit 105 notifies of security anomalies at a higher frequency than when the reduction level is medium.
[0033] Furthermore, when the reduction level is high, the recording unit 104 records simplified information including the details of the security anomaly, and significantly reduces the frequency of recording compared to when the reduction level is medium. In other words, when the reduction level is high, the recording unit 104 records security anomalies less frequently than when the reduction level is medium. When the reduction level is high, the notification unit 105 significantly reduces the frequency of notifications compared to when the reduction level is medium. In other words, when the reduction level is high, the notification unit 105 notifies of security anomalies less frequently than when the reduction level is medium. When the reduction level is stopped, the recording unit 104 stops recording and does not record security anomalies. The notification unit 105 stops notification and does not notify of security anomalies.
[0034] The reading unit 106 reads information including the details of security anomalies recorded by the recording unit 104. For example, if a read command to read information including the details of security anomalies is transmitted from the monitoring system 3 via the external communication device 20, the reading unit 106 reads the information including the details of the security anomalies as instructed. The read information is transmitted to the monitoring system 3 via the external communication device 20. Alternatively, if the diagnostic device is connected to the anomaly detection device 10, the reading unit 106 may read information including the details of security anomalies recorded by the recording unit and transmit the read information to the diagnostic device.
[0035] The external communication device 20 is a device that communicates with external devices and systems of the vehicle. The external communication device 20 includes an external communication unit 200. The external communication unit 200 is a communication controller that controls communication with the outside world. The external communication unit 200 transmits notification information to the monitoring system 3 based on notification instructions from the controller 100. In addition, when the external communication unit 200 receives a read instruction from the monitoring system 3, it outputs a read instruction to the controller 100.
[0036] Next, an example of the procedure for executing the anomaly detection method according to this embodiment will be described using Figure 4. Figure 4 is a diagram showing an example of a flowchart of the anomaly detection method executed by the anomaly detection device according to this embodiment. In step S1, the controller 100 determines the state of the vehicle 2. In step S2, the controller 100 detects a security anomaly in the in-vehicle network. In step S3, the controller 100 determines whether the state of the vehicle 2 is a critical state. A critical state is, for example, when automatic driving is in progress. If the controller 100 determines that the vehicle 2 is in a critical state, it proceeds to step S7. That is, if the controller 100 is in automatic driving mode, it proceeds to step S7. If the controller 100 determines that the state of the vehicle 2 is not a critical state, it proceeds to step S4. In step S4, the controller 100 determines whether the risk is extremely low. For example, if 80% or more of the determination elements are low risk, it is determined that the risk is extremely low. If the controller 100 determines that the risk is extremely low, it proceeds to step S8. If the controller determines that the risk is not extremely low, the controller 100 proceeds to step S5.
[0037] In step S5, the controller 100 determines whether the average risk value is between 2.5 and 3. If it determines that the average risk value is between 2.5 and 3, the controller 100 proceeds to step S9. If it determines that the average risk value is not between 2.5 and 3, the controller 100 proceeds to step S6. In step S6, the controller 100 determines whether the average risk value is between 1.5 and 2.5. If it determines that the average risk value is between 1.5 and 2.5, the controller 100 proceeds to step S10. If it determines that the average risk value is not between 1.5 and 2.5, the controller 100 proceeds to step S11.
[0038] In step S7, the controller 100 sets the reduction level to no reduction. In step S8, the controller 100 sets the reduction level to stop processing. In step S9, the controller 100 sets the reduction level to low level. In step S10, the controller 100 sets the reduction level to medium level. In step S11, the controller 100 sets the reduction level to high level. In step S12, the controller 100 records and notifies of a security anomaly according to the reduction level set in any of steps S7 to S11. In the flowchart of Figure 4, a security anomaly is detected in step S2, but if no security anomaly is detected, the controller 100 may return to step S1 and repeat the flow until a security anomaly is detected. Also, in the flowchart of Figure 4, the reduction level is determined based on the calculation of a risk value, but the calculation of a risk value is not a mandatory configuration, and other methods that allow the reduction level to be set may be used. Furthermore, setting a reduction level is not a mandatory configuration; any method that determines the content and frequency of recordings and notifications according to the vehicle's condition is acceptable and is not particularly limited.
[0039] As described above, in the anomaly detection device and anomaly detection method according to this embodiment, the controller determines the status of the vehicle, detects a security anomaly in the vehicle's in-vehicle network, determines the content of the security anomaly to be recorded and communicated, and the frequency of recording and communicating the security anomaly according to the status of the vehicle, and records and communicates the security anomaly according to the determined content and frequency. This makes it possible to control the load required to communicate the security anomaly according to the status of the vehicle.
[0040] Further, in the abnormality detection device and the abnormality detection method according to the present embodiment, the state of the vehicle includes at least any one of the weather around the vehicle, the temperature around the vehicle, the time zone in which the vehicle is traveling, the road surface on which the vehicle is traveling, the place where the vehicle is traveling, the speed state of the vehicle, the steering state of the vehicle, the parking location of the vehicle, and the automatic driving state of the vehicle. Thereby, for each state of the vehicle, the content and frequency of recording and communicating security abnormalities can be determined.
[0041] Further, in the abnormality detection device and the abnormality detection method according to the present embodiment, the controller calculates the risk to the safety of the vehicle with a security abnormality according to the state of the vehicle, and determines the content and frequency according to the risk. Thereby, for each state of the vehicle, the content and frequency of recording and communicating security abnormalities can be determined according to the risk of the security abnormality.
[0042] Further, in the abnormality detection device and the abnormality detection method according to the present embodiment, the controller determines the content and frequency so that the data amount of the content becomes larger and the frequency becomes higher as the risk is higher. Thereby, as the risk is higher, the data amount of the content to be recorded and communicated can be increased, and the frequency of recording and communicating can be increased.
[0043] Further, in the abnormality detection device and the abnormality detection method according to the present embodiment, when the controller determines that the automatic driving state of the vehicle is a state in which the vehicle is executing automatic driving, the controller calculates the highest risk. Thereby, when the vehicle is executing automatic driving, the risk of security abnormality can be highly evaluated.
[0044] Note that the embodiments described above are described to facilitate understanding of the present invention, and are not described to limit the present invention. Therefore, each element disclosed in the above embodiments is intended to include all design changes and equivalents belonging to the technical scope of the present invention.
[0045] 10... Abnormality detection device 100... Controller 101... Vehicle state determination unit 102... Detection unit 103... Recording information generation unit 104... Recording unit 105... Notification unit 106... Reading unit
Claims
1. An anomaly detection device performed by a controller, wherein the controller determines the state of a vehicle, detects a security anomaly in the vehicle's in-vehicle network, determines the content of the security anomaly to be recorded and communicated, and the frequency of recording and communicating the security anomaly according to the state of the vehicle, and records and communicates the security anomaly according to the determined content and frequency.
2. An anomaly detection device according to claim 1, wherein the state of the vehicle includes at least one of the following: the weather around the vehicle, the temperature around the vehicle, the time of day the vehicle is traveling, the road surface on which the vehicle is traveling, the location on which the vehicle is traveling, the speed state of the vehicle, the steering state of the vehicle, the parking location of the vehicle, and the automatic driving state of the vehicle.
3. An anomaly detection device according to claim 1 or 2, wherein the controller calculates the risk of the security anomaly to the safety of the vehicle according to the state of the vehicle, and determines the content and frequency according to the risk.
4. An anomaly detection device according to claim 3, wherein the controller determines the content and frequency such that the amount of data for the content increases and the frequency increases as the risk increases.
5. An anomaly detection device according to claim 3 or 4, wherein the controller determines that the vehicle's automatic driving state is a state in which the vehicle is performing automatic driving, and calculates the highest possible risk.
6. An anomaly detection method performed by a controller, wherein the controller determines the state of the vehicle, detects a security anomaly in the vehicle's in-vehicle network, determines the content of the security anomaly to be recorded and communicated, and the frequency of recording and communicating the security anomaly according to the state of the vehicle, and records and communicates the security anomaly according to the determined content and frequency.
Citation Information
Patent Citations
In-vehicle control device
JP2020141318A
Fraud handling method and fraud handling device
WO2020022327A1
Abnormality detection device, security system, and abnormality notification method
WO2023002634A1